Thursday, March 11, 2010

Bookmark and Share

Archive for the ‘Assessments’ Category

Why It Pays to Second-Guess Your Technology Assumptions

Ed’s latest column for ECT/TechNews World takes a look at the benefits of challenging your technology assumptions:

One of the many pitfalls of information security is the illusion of permanence that surrounds many longstanding tools, policies and ways of doing business. Too often, the fact that “it’s always been done that way” clouds our judgment and blinds us to a system’s holes. To avoid that mistake, it’s time to learn how to second-guess yourself.

Read the rest of the article here.

Bookmark and Share

FISAP: InfoSecurity’s Muzak

I came across a Computer World article this morning about “new standards” for doing security vendor assessment. I got all excited for a few minutes until I got to the part about how it’s a BITS initiative, but I decided to keep an open mind and do some research on it anyway. After all, I’ve said all along that I think the goal of having a common vendor score-card would be good for the industry (not to mention that it’s a good way to make money for those of us in the scoring business). Needless to say, I was disappointed by what I found.

Overall, I found the FISAP documents on the BITS site to be lacking in specificity (the FAQ, the program overview, etc.) The real “coup de grace” came, though, when I found out that the FISAP program is really (more or less) the BITS outsourcing workgroup with a new name; they’ve taken the long, vague, and toothless outsourcing documents we’ve all grown to love and “presto chango” made them into the core of the FISAP program. Seriously, this is from the program overview:

The Financial Institution Shared Assessments Program was conceived by the BITS IT Service Providers Working Group and leverages two groundbreaking outsourcing guides: the BITS IT Service Provider Expectations Matrix, a risk management tool for financial institutions, and the BITS Framework for Managing
Risk for IT Service Provider Relationships.


Bummer. I know a lot of people worked hard on these documents, so I really hate downplaying their achievements – but sometimes you just have to say what needs to be said. These documents are painful (I can say this without worry of hurting anybody’s feelings since these documents are all written by commitee anyway.) They’re skillfully worded not to prescribe anything, they state the obvious in the “eat your vegetables” kind of way, and they’re incredibly long – they’re like the “muzak” of security guidance.

Is that too harsh? Look, time is valuable. A 125 page document that doesn’t tell me anything wastes my time. This kind of long valuless document (nicely worded though it may be) is worse than useless to me. Useless would be if it required a small investment in time to read and provided a correspondingly small value – in that case, the energy spent reading it would roughly equal the value I got from it (“net zero”.) “Worse than useless” is when a large investment in time is required (like the time it takes ot read 125 pages) and provides minimal value – that’s a “net negative” – meaning I would have been better off if I had not read it. If you still think it’s too harsh, take a look for yourself – I don’t find it valuable, but that’s just me…

So how seriously do I think the industry will take FISAP? Maybe about as seriously as they take the BITS certification initiative. As per the BITS site, there are three products certified by BITS in their decade-long history (that’s an average of one every 3 years 4 months). Ouch.

Bookmark and Share
“A robust security posture comes from understanding the business and the people in it.”
Blog Cloud

The Law: Fear It Administrative Cruft (16)
Analysts (31)
Apple (25)
AppSec (12)
Assessments (2)
Auditors (2)
Biometrics (4)
Blogs (13)
Breaches (21)
Buzzwords (2)
By Grabthar's Hammer!! (1)
Certifications (1)
Change Management (1)
Cheezburger Network (1)
Chupacabra (1)
Cloud Computing Security (4)
Collaborative Strategy Guild (2)
Compliance (4)
Copyright (9)
Credit Cards (3)
Crypto (11)
CXO Summit 2010 (1)
Cyberterrorism (2)
Data Protection (1)
DHS (25)
eBay (1)
Emergence (1)
End-to-End Encryption (1)
England (1)
Financial Fraud (1)
FISAP (1)
Forensics (5)
FTC Red Flad Rules (1)
FUD (12)
gnisreveR (2)
Google (2)
Holidays! (3)
Humor (16)
Identity Theft (4)
James Bond Shiz (1)
Legal Shiz (13)
Linux (3)
Malware (35)
Marketing and PR (9)
Messaging Security (1)
Microsoft (26)
Monoculture (3)
Mouth-Frothing (2)
Musings (17)
Open Source (3)
Oracle (21)
Outsourcing (4)
Paris Hilton (1)
Passwords (1)
PCI (4)
Phish-Eye (8)
Phones (5)
Planes (1)
Privacy (1)
Programming (1)
QDSP Blues (15)
Research (30)
Resources (6)
Rhesus Monkeys (2)
Risk Management (18)
RSA 2009 (1)
RSA 2010 (1)
SAML (1)
SAN (1)
SC Mag Blues (1)
SCADA (1)
Security Curve (8)
SecurityCurve Speaking (2)
SIEM and Log Management (5)
Social Networking (1)
SOX (1)
Speaking (2)
Spinach (1)
Spy Stuff (1)
Stealing Stuff (8)
Storage (1)
Symantec (7)
Tarot (1)
Teleological suspension of the ethical (3)
The Great Borack (1)
The Law: Fear It (10)
The Old Man of the Mountain (1)
The Regs (5)
Tokenization (1)
Useless Shizz (13)
Vendors (37)
Virtual Worlds (2)
Voting (2)
Vulnerabilities (40)
Walt Disney (2)
Wi-Fi (16)

WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.

Archives